CVE-2013-2459: Integer Overflow
It was discovered that various parts of the AWT component did not properly perform integer overflow checks. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "integer overflow checks."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2459?
CVE-2013-2459 has a severity rating of 7.5, indicating it is critical.
How can I fix CVE-2013-2459?
To fix CVE-2013-2459, update your Java Runtime Environment (JRE) to version 1.7.0-update21 or later.
Which versions of JRE are affected by CVE-2013-2459?
CVE-2013-2459 affects Oracle JRE versions 1.7.0 up to and including 1.7.0-update21.
Does CVE-2013-2459 affect JDK as well?
Yes, CVE-2013-2459 also affects specific versions of Oracle JDK 6 and 7.
What type of vulnerability is CVE-2013-2459?
CVE-2013-2459 is an integer overflow vulnerability that can allow unauthorized actions in a Java application.